CVE-2026-19766
nicheAuthentication Bypass Leads to Privileged RCE in HPE Aruba Networking Fabric Composer
CVE-2026-19766 is an improper authentication flaw (CWE-287) in the underlying operating system of HPE Aruba Networking Fabric Composer (AFC), HPE's data center fabric orchestration appliance/software. An unauthenticated attacker positioned on an adjacent network segment (e.g., the same management or fabric network) can bypass authentication and execute arbitrary code as a privileged user on the underlying OS. Successful exploitation results in complete compromise of the AFC host, including full confidentiality, integrity, and availability impact per the CVSS scope-changed rating of 9.6 (critical). Only organizations running HPE Aruba Networking Fabric Composer are affected, and because the attack vector is adjacent rather than internet-facing, exposure is largely limited to those with untrusted access to AFC's network environment. No public proof-of-concept, KEV listing, or known exploitation exists, and EPSS currently assigns a low 0.3% probability of exploitation within 30 days.
What to do: Check HPE's security bulletin (HPE Security Alert) for this CVE and upgrade Fabric Composer to the fixed release it specifies, as affected/fixed versions are not listed here. In the interim, restrict access to the AFC management and fabric networks to trusted operators and isolate the underlying OS interfaces from untrusted adjacent segments. Monitor HPE advisories for updated guidance, since no public exploit or in-the-wild exploitation has been reported.
| arubanetworks (HPE) HPE Aruba Networking Fabric Composer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.
- Vendors
- arubanetworks
- Products
- fabric composer
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.